Smile Simulation & AI
In Saudi Arabia, a patient's photo is personal data, and the PDPL sets rules for handling it. Here is a plain-language, non-legal overview of what dental clinics should understand — and why to consult counsel.
Simulated preview — a visualization aid, not a guaranteed outcome.
In Saudi Arabia, a patient's photo is personal data, and the Personal Data Protection Law (PDPL) sets out how personal data must be handled — so a dental clinic using patient images owes it to itself to understand consent, transparency, and cross-border processing at a high level, and to take proper legal advice. This is a plain-language overview for orientation, not legal advice. Here is what dental clinics should understand about patient photos under the PDPL, and why counsel matters.
Important: this article is general educational information, not legal advice. Data-protection requirements are detailed and change; consult a qualified adviser and the official regulator guidance for your specific situation.
Because it identifies an individual, and facial images are inherently personal — often treated as especially sensitive. A photograph of a patient's face, used for a preview, a record, or marketing, is personal data about an identifiable person, which brings it within the scope of data-protection law. Health-related and biometric-adjacent data typically attract heightened care. This is not a reason to avoid using patient photos, which are essential to cosmetic dentistry, but a reason to handle them thoughtfully: with a lawful basis, transparency, and appropriate safeguards. Recognising that a patient's image is regulated personal data is the starting point for handling it responsibly. The broader ethics are in AI ethics in the dental chair.
At a high level, the PDPL reflects principles common to modern data-protection regimes: a lawful basis for processing (often consent), transparency about how data is used, purpose limitation and data minimisation, appropriate security, respect for individuals' rights, and conditions around transferring data outside the Kingdom. For a dental clinic, that translates into obtaining proper consent for using a patient's photo, being clear about the purpose, not using the image for unrelated purposes, keeping it secure, and being mindful of where and how any cloud processing occurs. The specifics and the current requirements are matters for your legal adviser and the official regulator guidance, not this overview.
That consent should be informed, specific, and freely given — and that consent for one purpose does not automatically cover another. A patient consenting to a photo for their own preview or clinical record has not thereby agreed to its use in marketing, which typically needs separate, explicit permission. Consent should be genuine, not buried in unread paperwork, and the patient should understand what they are agreeing to. Good consent practice is both a legal expectation and simply respectful. Keeping clear records of what each patient consented to, for which purpose, is prudent. The consent-quality principles are in AI ethics in the dental chair.
This is where clinics should be most careful, because cloud tools may process data outside the Kingdom, which data-protection regimes typically regulate. If a clinic uses a cloud preview tool, it should understand where the patient's photo is processed, what is stored and for how long, and whether cross-border processing is handled in line with the applicable rules. The right posture is to choose transparent tools and to take advice on cross-border transfer. Our own data position is written plainly — Your photo is processed transiently to create the preview and is never stored by Smileproof. Our AI provider may retain inputs for a limited period (up to 55 days) solely for abuse monitoring under its data-processing terms. It is never used to train models. — and we are candid about what is and is not yet available; the vendor questions to ask anyone are in the privacy guide. Whether any given arrangement meets your obligations is a question for your adviser.
Modern data-protection regimes generally give individuals rights over their personal data — such as being informed about its use, accessing it, correcting it, and in some cases having it deleted. For a dental clinic, this means being able to respond to a patient who asks what image data you hold, corrects a record, or withdraws consent. Building simple processes to honour such requests is part of responsible data handling. The exact rights, and how they apply, are defined by the law and its regulations and should be confirmed with your adviser. Treating patients' data rights as real and answerable is both compliant in spirit and good practice.
Orientation, not legal advice — a starting point to discuss with counsel.
This is a conversation-starter for your adviser, not a substitute for one.
By being transparent about data, which is exactly what responsible handling requires — though the clinic remains responsible for its own obligations. A tool that clearly states what it stores, for how long, whether it trains on inputs, and where it processes data gives the clinic the information it needs to make and evidence good decisions, and to answer patients honestly. A tool that is vague about data makes compliance harder. Choosing transparent tools, keeping good consent practices, and taking proper advice together form a responsible posture. Smileproof does not claim to determine your PDPL compliance; it aims to be transparent enough to support it, and we say plainly what our tools do with a patient's photo. The same honesty runs through the images themselves: every preview a clinic shows remains a visualization aid, not a guarantee, so honesty about the data and honesty about the result go hand in hand. The compliance-honesty theme is in why most dental AI tools quietly ignore HIPAA.
Want our data practices in writing to review with your adviser? book a demo — qualified clinics get a trial set up personally after a short demo.
Book a 20-minute demo and leave with a 30-day pilot — 100 previews and 5 lab reports, no card.
Book a demo →